Status

Spectre and Meltdown security vulnerabilities

Catalyst Cloud has assembled a response team to address the recently announced Spectre and Meltdown vulnerabilities that affect Intel, AMD, and ARM processors.

We have categorised these vulnerabilities as critical and will perform emergency outages to apply patches to our affected servers as soon as possible. As part of these emergency outages customers' compute instances will be rebooted.

All operating system vendors are expected to provide security updates to address these vulnerabilities soon. Customers are reminded of the importance to apply these security updates to your compute instances as soon as possible.

The status page will be updated regularly with progress and more information as it becomes available.

CVE-2017-5753
CVE-2017-5715
CVE-2017-5754

Patching of compute servers

2018-01-10 17:30 All compute servers have been patched in Hamilton, Porirua, and Wellington.

2018-01-10 10:18 Patching of the Wellington region is expected to be concluded on Wednesday 10 January.

2018-01-08 23:10 All compute servers patched in Hamilton and Porirua. Wellington servers will be patched on Tuesday 09 January.

2018-01-08 15:00 Microcode updates applied to all compute nodes in all regions. Pending reboot to make it effective. Reboot of compute instances is expected to start around 4 pm.

2018-01-06 Testing the updates and patching procedures to ensure they will work as expected. Testing is expected to be completed on Monday morning.

2018-01-05 Developing patching procedures.

Operating system images

The following public operating system images provided by Catalyst or our partners have been updated with the Meltdown and Spectre patches:

Image

Status

Comments

atomic-7-x86_64

Done

centos-6.5-x86_64

Waiting for the CentOS community to release new image.

centos-6.6-x86_64

Done

centos-7-x86_64

Done

coreos-stable-x86_64

Done

debian-9-x86_64

Done

debian-8-x86_64

Done

debian-7-x86_64

Waiting for Debian community to release new image.

ubuntu-12.04-x86_64

Waiting for Canonical to release new images.

ubuntu-13.10-x86_64

Waiting for Canonical to release new images.

ubuntu-14.04-x86_64

Done

ubuntu-16.04-x86_64

Done

windows-server-2012r2-x86_64

Done

windows-server-2016-x86_64

Done

Hamilton region

All services are operational.

2018-01-08 17:00 Compute servers are being rebooted to apply the patch for Spectre and Meltdown.

2018-01-08 18:25 Most compute servers patched. We expect to finish patching of this region around 7 pm.

2018-01-08 19:30 All compute servers patched and back online.

Porirua region

All services are operational.

2018-01-08 17:45 Compute servers are being rebooted to apply the patch for Spectre and Meltdown.

2018-01-08 21:58 Most compute servers patched. We expect to finish patching of this region around 11 pm.

2018-01-08 23:10 All compute servers patched and back online.

Wellington region

All services are operational.

2018-01-09 13:45 Compute servers are being rebooted to apply the patch for Spectre and Meltdown.

2018-01-10 10:18 Last compute servers in the Wellington region are being rebooted to apply the patch.